CVE-2008-3573: Medium severity php-nuke vulnerability
The CAPTCHA implementation in (1) Pligg 9.9.5 and possibly (2) Francisco Burzi PHP-Nuke 8.1 provides a critical random number (the tsrandom value) within the URL in the SRC attribute of an IMG element, which allows remote attackers to pass the CAPTCHA test via a calculation that combines this value with the current date and the HTTP User-Agent string.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-3573?
CVE-2008-3573 is considered critical due to its ability to bypass CAPTCHA security mechanisms.
Which software versions are affected by CVE-2008-3573?
CVE-2008-3573 affects Pligg version 9.9.5 and PHP-Nuke version 8.1.
How do I fix CVE-2008-3573?
To fix CVE-2008-3573, update to the latest versions of Pligg and PHP-Nuke that address this vulnerability.
What type of attack can be executed using CVE-2008-3573?
CVE-2008-3573 allows remote attackers to bypass CAPTCHA by exploiting vulnerabilities in the random number generation.
Is there a workaround for CVE-2008-3573?
There are no documented workarounds for CVE-2008-3573; updating the software is the recommended action.